Skip to main content
RedTiger Stealer: GoFile + Discord-Webhook Exfiltration operation cover
IntermediateXDRSIEMFirewallPRO

RedTiger Stealer: GoFile + Discord-Webhook Exfiltration

A single-host smash-and-grab infostealer intrusion. An artist ran a PyInstaller-compiled executable disguised as a Roblox FPS-unlocker mod that was actually the open-source RedTiger stealer. In one short burst it unpacked to Temp, blackholed security-vendor domains in the hosts file, persisted via the Startup folder, injected JavaScript into the Discord client, and archived Discord tokens, browser credentials and cards, a crypto wallet, a webcam frame, and a screenshot. Exfiltration ran in two stages over legitimate cloud: the loot ZIP was uploaded to GoFile, then the download link plus victim recon was posted to a Discord webhook. Reconstruct the kill chain from SIEM, endpoint XDR, and perimeter firewall telemetry, and classify the key ATT&CK techniques.

55m
7 tasks
50 points
Pro

Start this operation

Investigation Tasks

Complete each task by investigating alerts and submitting your findings.

1

Incident brief

0

Orient yourself before pivoting into the data. This is a no-answer briefing checkpoint.

2

Find the initial payload

40

Every later event traces back to one execution on one workstation. Identify the file the artist was tricked into running.

Hint available
3

Classify the defense-evasion step

35

Before stealing anything, the payload tried to blind the host's security tooling. Classify what it did.

Hint available
4

Pin the persistence artifact

40

The stealer arranged to come back at the next logon. Provide the full path it planted to survive a reboot.

Hint available
5

Trace stage one of the exfiltration

40

The stolen data left the network first. Identify the anonymous cloud-storage host that received the loot archive.

Hint available
6

Recover the operator's notification channel

40

Stage two told the operator where to grab the loot. Recover the exact channel the link was sent to.

Hint available
7

Classify the exfiltration technique

35

Name how the stolen data was carried off the network. Classify the exfiltration technique the archive upload used.

Hint available

7 tasks · 230 points total

Training Tools

Skills You'll Build

Investigate realistic security alerts
XDR log analysis
SIEM log analysis
Firewall log analysis
MITRE ATT&CK® technique identification
Triage decisions: escalate, investigate, or close
Evidence collection and documentation
Job-ready incident response methodology
Intermediate

Requires foundational alert triage skills. Multiple data sources to correlate.

Prerequisites

  • Basic understanding of security alerts
  • Familiarity with XDR concepts
  • Familiarity with SIEM concepts
  • Familiarity with Firewall concepts

Ready to investigate?

More Operations

View all
IntermediateCloudEmail

Consent Granted: Malicious OAuth App Mailbox BEC

A consent-phishing intrusion where an adversary-in-the-middle proxy steals a finance analyst's Microsoft 365 session, then the attacker tricks her into granting a malicious multitenant OAuth application delegated mailbox permissions. The app gets its own client secret for durable access, reads her mailbox over Microsoft Graph, hides vendor replies with an inbox rule, and sends a fraudulent bank-detail-change reply into a live settlement thread. Work the Entra consent and permission-grant audit, the service-principal credential change, the Graph mailbox operations, and the email evidence to reconstruct the chain.

50m50 pts
IntermediateFirewallSIEM

RapperBot: From SSH Brute-Force to DDoS and Hidden XMRig Mining

A Mirai-derived DDoS botnet brute-forces SSH on an internet-exposed Linux edge gateway, persists an attacker SSH key in root's authorized_keys, pulls a Bash stager, and drops a single merged binary that fuses the RapperBot DDoS client with an embedded XMRig Monero miner. The bot registers with a hardcoded C2 over a custom binary protocol, floods an external victim with UDP/TCP/HTTP traffic, and quietly mines Monero through two proxy pools hosted on the C2 IP itself. Reconstruct the chain from SIEM, endpoint XDR, and perimeter firewall telemetry.

1h50 pts
IntermediateSIEMFirewall

Hidden in the Pixels: LSB Steganography Exfil From an Infected Endpoint

A LummaC2/Vidar-style infostealer smash-and-grab. A finance analyst was tricked by a fake CAPTCHA (ClickFix) into pasting an mshta command into the Run box, which staged hidden PowerShell, downloaded the Lumma stealer, and harvested browser credentials, cookies, and wallet artifacts. To smuggle the loot out, the operator LSB-encoded the stolen blob into an oversized PNG and uploaded it to a public image host, off the command-and-control channel. Reconstruct the chain from SIEM and perimeter firewall telemetry and classify the key ATT&CK techniques.

30m50 pts